CVE-2014-3369: High severity cisco telepresence vcs and expressway major vulnerability
Published Oct 19, 2014
·Updated
The SIP IX implementation in Cisco TelePresence Video Communication Server (VCS) and Expressway Software before X8.1.1 allows remote attackers to cause a denial of service (device reload) via crafted SDP packets, aka Bug ID CSCuo42252.
Affected Software
2 affected components
Cisco Expressway Software<=x8.1
Cisco Telepresence Video Communication Server Software<=x8.1
Event History
Oct 19, 2014
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-3369?
CVE-2014-3369 has been classified as a denial of service vulnerability.
2
How do I fix CVE-2014-3369?
To fix CVE-2014-3369, you should upgrade to the software version X8.1.1 or later.
3
What type of attack is possible with CVE-2014-3369?
CVE-2014-3369 allows remote attackers to cause a denial of service by sending crafted SDP packets.
4
Which Cisco products are affected by CVE-2014-3369?
Cisco TelePresence Video Communication Server and Expressway Software versions up to X8.1 are affected by CVE-2014-3369.
5
Is there a workaround for CVE-2014-3369?
There are no known workarounds for CVE-2014-3369, so upgrading is recommended.